Virtual Private Networks (Vpns - NETGEAR FVX538 - ProSafe VPN Firewall 200 Router Reference Manual

Vpn firewall
Hide thumbs Also See for FVX538 - ProSafe VPN Firewall 200 Router:
Table of Contents

Advertisement

ProSafe VPN Firewall 200 FVX538 Reference Manual

Virtual Private Networks (VPNs)

When implementing virtual private network (VPN) tunnels, a mechanism must be used for
determining the IP addresses of the tunnel end points. The addressing of the firewall's dual WAN
port depends on the configuration being implemented:
Table B-2. IP addressing requirements for VPNs in dual WAN port systems
Configuration and WAN IP address
VPN Road Warrior
(client-to-gateway)
VPN Gateway-to-Gateway Fixed
VPN Telecommuter
(client-to-gateway through
a NAT router)
a. All tunnels must be re-established after a rollover using the new WAN IP address.
For the single gateway WAN port case, the mechanism is to use a fully-qualified domain name
(FQDN) when the IP address is dynamic and to use either an FQDN or the IP address itself when
the IP address is fixed. The situation is different when dual gateway WAN ports are used in a
rollover-based system.
Rollover Case for Dual Gateway WAN Ports
Rollover for the dual gateway WAN port case is different from the single gateway WAN port
case when specifying the IP address of the VPN tunnel end point. Only one WAN port is active
at a time and when it rolls over, the IP address of the active WAN port always changes. Hence,
the use of a fully-qualified domain name is always required, even when the IP address of each
WAN port is fixed.
Note: Once the gateway router WAN port rolls over, the VPN tunnel collapses and must
be re-established using the new WAN IP address.
B-10
Single WAN Port
(reference case)
Fixed
Allowed
(FQDN optional)
Dynamic
FQDN required
Allowed
(FQDN optional)
Dynamic
FQDN required
Fixed
Allowed
(FQDN optional)
Dynamic
FQDN required
v1.0, March 2009
Dual WAN Port Cases
Rollover
Load Balancing
a
FQDN required
Allowed
(FQDN optional)
FQDN required
FQDN required
FQDN required
Allowed
(FQDN optional)
FQDN required
FQDN required
FQDN required
Allowed
(FQDN optional)
FQDN required
FQDN required
Network Planning for Dual WAN Ports

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fvx538v1 - prosafe vpn firewall dual wanProsafe fvx538

Table of Contents